ZeroHour
Security Affairspublished ()ingested @securityaffairs

Threat actors exploited SolarWinds Serv-U bug CVE-2024

highThreat actor exploited in the wildimportance 60CVE-2024-28995

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-28995
Unauthenticated Path Traversal File-Read in SolarWinds Serv-U

CVE-2024-28995 is a directory traversal flaw (CWE-22) in SolarWinds Serv-U, the vendor's managed file transfer/FTP server. Per the CVSS vector, it is reachable over the network with low attack complexity and requires no privileges or user interaction, meaning an unauthenticated remote attacker can trigger it. By sending traversal sequences that escape the intended directory, the attacker gains the ability to read sensitive files on the host machine (high confidentiality impact, with no integrity or availability impact). Any organization running SolarWinds Serv-U is potentially affected, particularly instances exposed to the internet. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-17, threat actors were reported exploiting it in the wild, and EPSS puts the 30-day exploitation probability at 99.6%, although no public proof-of-concept is known.

Do: Apply SolarWinds' patch or hotfix for Serv-U per the vendor's July 2024 PSIRT advisory, prioritizing internet-facing instances; if mitigations cannot be applied, CISA's required action is to follow vendor instructions or discontinue use of the product. In the meantime, restrict Serv-U exposure to trusted networks and review FTP/web server access logs for traversal-style requests that could indicate file reads or exfiltration.

7.5100% KEV
  • SolarWinds Serv-U
largelow tens of thousands of internet-exposed Serv-U file-transfer servers
Full article310 words · extracted from securityaffairs.com · click to collapse

Threat actors are actively exploiting a recently discovered vulnerability in SolarWinds Serv-U software using publicly available proof-of-concept (PoC) code.

Threat actors are actively exploiting a recently discovered vulnerability, tracked as CVE-2024-28995, in SolarWinds Serv-U software.

The vulnerability CVE-2024-28995 is a high-severity directory transversal issue that allows attackers to read sensitive files on the host machine. The flaw was discovered and reported by Hussein Daher.

Experts at threat intelligence firm GreyNoise reported that threat actors are actively exploiting a public available proof-of-concept (PoC) exploit code.

“SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.” reads the advisory.

The flaw was disclosed on June 6, it impacts Serv-U 15.4.2 HF 1 and previous versions.

GreyNoise researchers started investigating the issue after Rapid7 published technical details about the flaw and PoC exploit code. GitHub users bigb0x also shared a proof-of-concept (PoC) and a bulk scanner for the SolarWinds Serv-U CVE-2024-28995 directory traversal vulnerability.

“The vulnerability is very simple, and accessed via a GET request to the root (/) with the arguments InternalDir and InternalFile set to the desired file. The idea is that InternalDir is the folder, and they attempt to validate there are no path-traversal segments (../). InternalFile is the filename.” reported GreyNoise.

GreyNoise researchers started observing exploitation attempts for this issue over the weekend.

Some failed attempts relied on copies of publicly available PoC exploits, others attempts were associated to attackers with a better knowledge of the attack.

“We see people actively experimenting with this vulnerability – perhaps even a human with a keyboard. The route between this vulnerability and RCE is tricky, so we’ll be curious to see what people attempt!” states GreyNoise.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, SolarWinds Serv-U)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/164806/hacking/solarwinds-serv-u-cve-2024-28995-exploit.html